πͺπΈ
alferez
2026-07-21 08:46:23
(16 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-21 08:43:21
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co. ...
show more
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co.zm): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 04:43:17.140871 2026] [security2:error] [pid 3393:tid 3433] [client 102.220.158.247:22709] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.220.158.247 (+1 hits since last alert)|atlasrecordssearch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "atlasrecordssearch.com"] [uri "/xmlrpc.php"] [unique_id "al8xJeKQ8Utmb2MGI3EHGgAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-21 07:41:04
(17 hours ago)
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co. ...
show more
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co.zm): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 03:40:59.006112 2026] [security2:error] [pid 10044:tid 10066] [client 102.220.158.247:22734] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.220.158.247 (+1 hits since last alert)|munatseng.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "munatseng.org"] [uri "/xmlrpc.php"] [unique_id "al8iivjkOwDCK0SLL4YBygAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 13:23:11
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co. ...
show more
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co.zm): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 09:23:07.440908 2026] [security2:error] [pid 2865523:tid 2865523] [client 102.220.158.247:22630] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.220.158.247 (+1 hits since last alert)|jacquelineperriam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jacquelineperriam.com"] [uri "/xmlrpc.php"] [unique_id "al4hO3EQmmrLoU4GG6RaagAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-07-20 12:50:43
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 12:48:52
(1 day ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 07:05:33
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co. ...
show more
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co.zm): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 03:05:27.109673 2026] [security2:error] [pid 32265:tid 32265] [client 102.220.158.247:22565] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.220.158.247 (+1 hits since last alert)|truthsabouthealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "truthsabouthealthcare.com"] [uri "/xmlrpc.php"] [unique_id "al3It8EfKKe0Lmu1uZ7A-QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-18 09:39:05
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
π«π·
SpaceHost-Server
2026-07-17 14:32:43
(4 days ago)
102.220.158.247 - - [17/Jul/2026:16:32:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12 ...
show more
102.220.158.247 - - [17/Jul/2026:16:32:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.0; WordPress/6.2; http://site35899960.com"
102.220.158.247 - - [17/Jul/2026:16:32:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "WordPress.com; https://wordpress.com"
102.220.158.247 - - [17/Jul/2026:16:32:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack by WordPress.com"
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 14:19:36
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co. ...
show more
(mod_security) mod_security (id:240335) triggered by 102.220.158.247 (102-220-158-247.simbafiber.co.zm): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 10:19:28.950220 2026] [security2:error] [pid 47295:tid 47295] [client 102.220.158.247:22729] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.220.158.247 (+1 hits since last alert)|furbabieslivesmatter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "furbabieslivesmatter.com"] [uri "/xmlrpc.php"] [unique_id "alo58I4Y3BLPCzl2pTu9uwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
SpaceHost-Server
2026-07-17 14:17:19
(4 days ago)
102.220.158.247 - - [17/Jul/2026:16:16:59 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12 ...
show more
102.220.158.247 - - [17/Jul/2026:16:16:59 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.5; WordPress/6.4; http://site88795432.com"
102.220.158.247 - - [17/Jul/2026:16:17:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "WordPress.com; https://wordpress.com"
102.220.158.247 - - [17/Jul/2026:16:17:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.0; WordPress/6.3; http://site90480118.com"
show less
Hacking
Web App Attack
π©πͺ
F242
2026-07-17 13:46:41
(4 days ago)
Wordpress soft lock
Web App Attack
π©πͺ
LRob
2026-07-17 11:44:13
(4 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)
show less
Brute-Force
Web App Attack
πΊπΈ
kosada.com
2026-07-17 08:30:41
(4 days ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-05-02 02:25:06
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host